(keitai-l) Re: Amazon Japan Payment Security

From: <ariste_at_gol.com>
Date: 06/21/04
Message-Id: <E1BcDFz-0002ls-Q6@smtp01.dentaku.gol.com>
Hi Andrew,

Andrew Shuttleworth wrote:
>Just for interest I tried forwarding the full URL I sent earlier to a
>friend's DoCoMo phone. That person could visit the site but when they
>got to the purchase page they had to input a user name and password,
>whereas when I visited the same URL on my phone I had the option of
>1-click purchase (and from past experience this really does mean
>1-click). Therefore they must be using some sort of identifier to know
>that I am me and I assume this requires being an official menu site.

my information may be a bit old, but this can be done in a number of ways.
As I understand it

Docomo - in addition to official sites having access to a unique user
number (all phones), newer phones (503i and later, FOMA) having the send
userid permission enabled will also send a user number to any site when
the "utn" attribute is included in the link or form tag.

Vodafone - sends the phone serial number in the HTTP_USER_AGENT header

Au - sends the subscriber id in the HTTP_X_UP_SUBNO header

and one of these could be used id in lieu of cookie for userlogin.

Steve Veltema
Received on Mon Jun 21 04:06:00 2004